{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "4922cd26f03c1c71bf7dd6cbdb638e7e36a4a50b"
            },
            {
              "fixed": "d2844f3fcd058113acbe0aa110ab13ef28b98d9f"
            },
            {
              "fixed": "1bfc0547b81d5861443420d19b5ed2fd533cd17f"
            },
            {
              "fixed": "84781a1f3c5dc6650480be9329e6e8528939eaa0"
            },
            {
              "fixed": "96dd0af7597aba2d80cc97e2f66e8b72d30ba125"
            },
            {
              "fixed": "114af803e409a68e52516810ecd24df4d8ce0c68"
            },
            {
              "fixed": "74ec08f7b81c2726578039ca6dea0fec136c38ea"
            },
            {
              "fixed": "0cdc6cb242dd8d2731956fdf3390de094482a4b2"
            },
            {
              "fixed": "a8e04f3f894ccb52cfcd7e60125a9f35da4a616d"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.11.0"
            },
            {
              "fixed": "5.10.270"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.221"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.188"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.157"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.110"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.51"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89999.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: wacom: validate report length in wacom_intuos_pro2_bt_irq\n\nwacom_intuos_pro2_bt_irq() receives the wire report length in `len`\nbut never consults it before parsing. After the report-id gate it\nunconditionally calls wacom_intuos_pro2_bt_pen() and then, selected by\nfeatures.type, a fixed chain of sub-parsers, none of which receive\n`len`:\n\n\twacom_intuos_pro2_bt_pen(wacom);\n\tif (type == INTUOSP2_BT || type == INTUOSP2S_BT) {\n\t\twacom_intuos_pro2_bt_touch(wacom);\n\t\twacom_intuos_pro2_bt_pad(wacom);\n\t\twacom_intuos_pro2_bt_battery(wacom);\n\t} else {\n\t\twacom_intuos_gen3_bt_pad(wacom);\n\t\twacom_intuos_gen3_bt_battery(wacom);\n\t}\n\nEach sub-parser dereferences wacom-\u003edata at fixed offsets. The furthest\nbyte touched on each branch is:\n\n  INTUOSP2_BT / INTUOSP2S_BT: wacom_intuos_pro2_bt_pad() reads data[285]\n\t(the touchring byte), so the report must be at least 286 bytes;\n  INTUOSHT3_BT (\"gen3\"): wacom_intuos_gen3_bt_battery() reads data[45],\n\tso the report must be at least 46 bytes.\n\nfeatures.type is selected from the VID/PID id_table entry and\nwacom_setup_device_quirks() force-registers the pen/pad/touch inputs\nfor that type independent of the report descriptor, so a malicious or\nmalfunctioning paired/spoofed Bluetooth peripheral can advertise that\nVID/PID and send an undersized report that still satisfies the\ndata[0] == 0x80/0x81 gate. The driver then reads past the received\nreport and forwards the bytes to userspace via evdev (MSC_SERIAL /\nABS_MISC / ABS_WHEEL on the pen and pad input nodes), an out-of-bounds\nread with a concrete userspace read-back channel, and a true\nout-of-bounds read on transports whose backing buffer is sized to the\n(small) report descriptor rather than a fixed-size staging buffer.\n\nThis is the same class of bug commit 2f1763f62909 (\"HID: wacom: fix\nout-of-bounds read in wacom_intuos_bt_irq\") already hardened in the\nsibling wacom_intuos_bt_irq(), which guards each report id against its\nminimum length before parsing.\n\nGuard wacom_intuos_pro2_bt_irq() the same way: before parsing, reject\nreports shorter than the furthest offset the selected branch actually\ndereferences, warn, and bail out. Because the whole pen/touch/pad/\nbattery chain runs unconditionally per branch, a single up-front check\nagainst the maximum offset (286 bytes for INTUOSP2_BT/INTUOSP2S_BT,\n46 bytes for the gen3 branch) bounds every sub-parser. Returning 0 on\na short report also skips those calls for the same malformed report,\nwhich is the safe, conservative behavior.",
  "id": "CVE-2026-89999",
  "modified": "2026-09-18T03:30:28.135924978Z",
  "published": "2026-09-16T10:33:10.683Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0cdc6cb242dd8d2731956fdf3390de094482a4b2"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/114af803e409a68e52516810ecd24df4d8ce0c68"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/1bfc0547b81d5861443420d19b5ed2fd533cd17f"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/74ec08f7b81c2726578039ca6dea0fec136c38ea"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/84781a1f3c5dc6650480be9329e6e8528939eaa0"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/96dd0af7597aba2d80cc97e2f66e8b72d30ba125"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a8e04f3f894ccb52cfcd7e60125a9f35da4a616d"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d2844f3fcd058113acbe0aa110ab13ef28b98d9f"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89999.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89999"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "HID: wacom: validate report length in wacom_intuos_pro2_bt_irq"
}